ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ41ÖÜ

Ðû²¼Ê±¼ä 2019-10-21

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê10ÔÂ14ÈÕÖÁ20ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´53¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇISC BIND QNAME×îС»¯´úÂë¾Ü¾ø·þÎñ©¶´;Samsung Galaxy S10δÊÚȨ·ÃÎÊ©¶´£»Kubernetes API Server JSON/YAML½âÎö¾Ü¾ø·þÎñ©¶´£»Adobe Experience Manager CVE-2019-8088ÃüÁî×¢È멶´£»Adobe AcrobatºÍReaderÄÚ´æ´íÎóÒýÓÃÈÎÒâ´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǺ½Ô˾ÞÍ·Pitney BowesÔâÀÕË÷Èí¼þ¹¥»÷£¬¶à¸öϵͳ崻ú£»ÈüÃÅÌú¿ËÖÕ¶ËÄþ¾²²úÎïµÄ¸üе¼ÖÂÓû§É豸À¶ÆÁ£»Android 0day(CVE-2019-2215)µÄPoC´úÂëÒÑÐû²¼£»Êý°ÙÍòÑÇÂíÑ·EchoºÍKindleÉ豸Ò×ÊÜWiFi KRACK¹¥»÷£»Linux sudoȨÏÞÈƹý©¶´£¬¿ÉÒÔrootȨÏÞÖ´ÐÐÃüÁî¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí



1. ISC BIND QNAME×îС»¯´úÂë¾Ü¾ø·þÎñ©¶´
ISC BIND QNAME×îС»¯´úÂë´¦ÖôæÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹnamedÍ˳ö£¬Ôì³É¾Ü¾ø·þÎñ¹¥»÷¡£
https://kb.isc.org/docs/cve-2019-6476

2. Samsung Galaxy S10δÊÚȨ·ÃÎÊ©¶´
Samsung Galaxy S10Ö¸ÎÆÑéÖ¤´æÔÚÄþ¾²Â©¶´£¬ÔÊÐí¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìύδ¼ÈëÖ¸ÎÆ£¬¿É·ÃÎÊÊÖ»ú¡£
https://www.forbes.com/sites/gordonkelly/2019/10/15/samsung-galaxy-s10-note10-plus-fingerprint-reader-warning-upgrade-galaxy-s11

3. Kubernetes API Server JSON/YAML½âÎö¾Ü¾ø·þÎñ©¶´
Kubernetes API Server JSON/YAML½âÎö´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíͨ¹ýÊÚȨµÄÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄ¶ñÒâÇëÇ󣬿ɽøÐоܾø·þÎñ¹¥»÷¡£
https://github.com/kubernetes/kubernetes/issues/83253

4. Adobe Experience Manager CVE-2019-8088ÃüÁî×¢È멶´
Adobe Experience ManagerÃüÁî×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£
https://helpx.adobe.com/security/products/experience-manager/apsb19-48.html

5. Adobe AcrobatºÍReaderÄÚ´æ´íÎóÒýÓÃÈÎÒâ´úÂëÖ´ÐЩ¶´
Adobe AcrobatºÍReader´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄPDFÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-49.html


 >ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢º½Ô˾ÞÍ·Pitney BowesÔâÀÕË÷Èí¼þ¹¥»÷£¬¶à¸öϵͳ崻ú


×ðÁú¶¶È¦ - Ϊdu¶øÉú


È«Çòº½Ô˾ÞÍ·Pitney BowesÐû²¼ÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö²¿ÃÅϵͳÖжÏ£¬´Ó¶øÓ°ÏìÁË¿Í»§¶ÔÆäijЩ·þÎñµÄ·ÃÎÊ¡£Pitney BowesΪȫÇòÁè¼Ý150Íò¿Í»§Ìṩ·þÎñ£¬°üÂÞ90%µÄ²Æ¸»500Ç¿¹«Ë¾¡£Ä¿Ç°Óжà¸öPitney Bowes·þÎñÊܵ½Ó°Ï죬°üÂÞPitney BowesµÄÓʼþϵͳ²úÎï¡ £¿Í»§ÎÞ·¨ÔÚÆäÓʼþϵͳÉÏÔö²¹ÓÊ×Ê»òÉÏ´«½»Ò×£¬Ò²ÎÞ·¨·ÃÎÊÓ¢¹úºÍ¼ÓÄôóµÄSendPro Online²úÎï¼°Your AccountºÍPitney Bowes SuppliesÍøÉÏÉ̵꣬Õâ·´¹ýÀ´ÓÖÓ°ÏìÁ˶©ÔÄAutoInkºÍSupplies AppµÄ¿Í»§¡£¸Ã¹«Ë¾ÔÚÉùÃ÷ÖÐÌåÏÖ£¬Ä¿Ç°Ã»ÓÐÖ¤¾Ý±íÃ÷¿Í»§»òÔ±¹¤µÄÊý¾Ý±»²»Í×·ÃÎÊ£¬¸Ã¹«Ë¾ÕýÔÚÓëµÚÈý·½ºÏ×÷½øÐÐÊÓ²ìÓë½â¾öÎÊÌâ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/global-shipping-firm-pitney-bowes-affected-by-ransomware-attack/

2¡¢ÈüÃÅÌú¿ËÖÕ¶ËÄþ¾²²úÎïµÄ¸üе¼ÖÂÓû§É豸À¶ÆÁ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ÈüÃÅÌú¿ËΪÆäEndpoint Protection²úÎïÍƳöµÄÈëÇÖ¼ì²âÇ©Ãû¸üе¼ÖÂÓû§É豸·ºÆðÍ߽ⲢÏÔʾÀ¶ÆÁ£¨BSOD£©¡£¸ÃÎÊÌâÓ°ÏìÁËWin 7¡¢Win8¼°Win 10£¬Æ¾¾ÝÈüÃÅÌú¿ËµÄ±íÊö£¬ÔÚÔËÐÐLiveUpdateʱEndpoint Protection Client»áÏÔʾËÀÍöÀ¶ÆÁ£¬²¢ÏÔʾIDSvix86.sys/IDSvia64.sys·ºÆðÎÊÌ⣬µ¼ÖÂBAD_POOL_CALLER (c2)»òKERNEL_MODE_HEAP_CORRUPTION (13A)Òì³£¡£¸Ã¹«Ë¾»¹Ôö²¹³ÆÊÜÓ°ÏìµÄÈëÇÖ¼ì²âµÄÇ©Ãû°æ±¾Îª2019/10/14 r61£¬¸ÃÎÊÌâÒÑÔÚа汾2019/10/14 r62Öнâ¾ö¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/symantec-fixes-bad-ips-definitions-that-cause-a-windows-bsod/

3¡¢Android 0day(CVE-2019-2215)µÄPoC´úÂëÒÑÐû²¼

×ðÁú¶¶È¦ - Ϊdu¶øÉú


±¾Ô³õ¹È¸èÄþ¾²Ñо¿Ô±Maddie StoneÅû¶ÁËÒ»¸öAndroidÁãÈÕ©¶´£¨CVE-2019-2215£©£¬Æäʱ¹È¸èÌåÏÖ¸ÃÁãÈÕ©¶´ÔÚÒ°Íâ±»»ý¼«ÀûÓ᣽üÈÕ·ðÂÞÀï´ï´óѧGrant HernandezÔÚ²©¿ÍÖÐÐû²¼ÁËÒ»¸öеÄPoC¹¤¾ßQu1ckR00t£¬¹¥»÷Õß¿ÉÀûÓøù¤¾ß»ñµÃrootȨÏÞ²¢ÍêÈ«¿ØÖÆÉ豸¡£¸Ã¹¤¾ßûÓÐ×÷Ϊ´ò°üµÄAPKÎļþÐû²¼£¬¶øÊÇÒÔÔ´´úÂëµÄÐÎʽÔÚGitHubÉÏÐû²¼¡£HernandezÌåÏÖËûÖ»ÔÚPixel 2ÊÖ»úÉϲâÊÔ¹ýQu1ckR00t£¬²¢¾¯¸æûÓо­ÑéµÄÓû§²»Òª²âÊԸôúÂ룬·ñÔò»áÓÐϵͳ±äשºÍÊý¾Ý¶ªÊ§µÄ·çÏÕ¡£GoogleÒÑÔÚ2019Äê10ÔµÄAndroidÄþ¾²Í¨¸æ£¨Äþ¾²²¹¶¡·¨Ê½¼¶±ð2019-10-06£©ÖÐÐÞ²¹ÁËCVE-2019-2215 ¡£ÎªÁËÖÆÖ¹·ºÆðÎÊÌ⣬½¨ÒéÓû§°²×°ÐëÒªµÄ²¹¶¡·¨Ê½¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/security-researcher-publishes-proof-of-concept-code-for-recent-android-zero-day/

4¡¢Êý°ÙÍòÑÇÂíÑ·EchoºÍKindleÉ豸Ò×ÊÜWiFi KRACK¹¥»÷


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ƾ¾ÝESETµÄÒ»·Ý³ÂËߣ¬Ñо¿ÈËÔ±·¢ÏÖAmazon Echo 1stºÍAmazon Kindle 8thÉ豸ÈÔÈ»Êܵ½WiFi KRACK©¶´µÄÓ°Ï죬Õâ¿ÉÄÜÓ°ÏìÊý°ÙÍòÉ豸¡£KRACK©¶´ÊÇWPA2ЭÒé4´ÎÎÕÊÖÖеÄ©¶´£¨CVE-2017-13077ºÍCVE-2017-13078£©£¬¸Ã©¶´ÓÚ2017Äê10Ô±»¹ûÈ»¡£Æ¾¾ÝESETµÄ±íÊö£¬ÕâЩ©¶´¿ÉÄÜÔÊÐí¹¥»÷ÕßÖ´ÐÐDoS¹¥»÷¡¢ÆÆ»µÍøÂçͨÐÅ»òÖز¥¹¥»÷£¬À¹½ØºÍ½âÃÜÓû§´«ÊäµÄÃÜÂë»ò»á»°µÈÃô¸ÐÐÅÏ¢£¬Î±ÔìÊý¾Ý°üÉõÖÁ×¢ÈëÐÂÊý¾Ý°üµÈ¡£ESETÓÚ2018Äê10ÔÂ23ÈÕ֪ͨÁËÑÇÂíÑ·£¬ÑÇÂíÑ·ÔÚ2019Äê1ÔÂÒÑÏòÊÜÓ°ÏìµÄÉ豸ÍÆËÍÁËÏà¹ØÐÞ¸´²¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/millions-of-amazon-echo-and-kindle-devices-affected-by-wifi-bug/

5¡¢Linux sudoȨÏÞÈƹý©¶´£¬¿ÉÒÔrootȨÏÞÖ´ÐÐÃüÁî


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Linux sudoÆسöÌáȨ©¶´£¬¿ÉÈƹýRunasÓû§ÏÞÖÆÒÔrootȨÏÞÖ´ÐÐÃüÁî¡£¸Ã©¶´£¨CVE-2019-14287£©ÓÉÆ»¹ûÐÅÏ¢Äþ¾²²¿ÃŵÄJoe Vennix·¢ÏÖ£¬Èç¹û½«sudoÅäÖÃΪÔÊÐíÓû§ÒÔÈÎÒâÓû§Éí·ÝÔËÐÐÃüÁÔò¿ÉÒÔͨ¹ýÖ¸¶¨Óû§IDΪ-1»ò4294967295µÄ·½Ê½ÒÔrootÉí·ÝÔËÐÐÃüÁî¡£ÕâÊÇÒòΪ½«Óû§IDת»»ÎªÓû§ÃûµÄº¯Êý£¬»á½«-1£¨»òµÈЧµÄ4294967295£©ÎóÈÏΪ0£¬¶øÕâÕýºÃÊÇrootÓû§µÄUser ID¡£´ËÍ⣬ÓÉÓÚͨ¹ý-uÑ¡ÏîÖ¸¶¨µÄUser IDÔÚÃÜÂëÊý¾Ý¿âÖв»´æÔÚ£¬Òò´Ë²»»áÔËÐÐÈκÎPAM»á»°Ä £¿é¡£¸Ã©¶´Ó°Ïì°æ±¾1.8.28֮ǰµÄËùÓÐSudo°æ±¾¡£

Ô­ÎÄÁ´½Ó£º
https://www.sudo.ws/alerts/minus_1_uid.html